[curves] Balancing reduced-radix and full-radix performance for extra-strength primes

Trevor Perrin trevp at trevp.net
Mon Jan 19 20:58:27 PST 2015

On Mon, Jan 19, 2015 at 6:24 PM, Michael Hamburg <mike at shiftleft.org> wrote:
> On their “comparison” slide did they mention that the Ed448-Goldilocks and E-521 impls both use point compression, and therefore have a 10% penalty vs their Ted37919 numbers?  It seems a little dishonest if they didn’t.

I don't recall that being mentioned.  He probably assumed it was just
timing an x-coordinate Montgomery ladder, and didn't expect your
special point format.

(Maybe you should submit just an x-coordinate ladder to SUPERCOP.  I'd
like to see the numbers without decompression, this is inaccurate in
my spreadsheet too.)


More information about the Curves mailing list